Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

191–200 of 473 posts

Re: Blocked by Cloudflare

#191
> Anyone who uses a de-Googled Android phone has to go to great lengths to ensure hardware attestation is working correctly [...] or else they can’t using banking apps.

I have a relatively Google'd Android running lineageOS. It passes SafteyNet on a fresh install, but even that isn't good enough for one of my banking apps (or netflix) - they both also perform a CTS Profile (Compatibility Test Suite) check and block me from using the app if they don't like what they see.

I ultimately had to root the phone to be able to use my bank's app. Rooting allowed me to use a fake CTS Profile, and then because it was rooted, SafteyNet started failing and I had to install a bypass to work around that.

Now everything works great, except OS updates un-root the phone and then "secure" apps stop working again.

(Oh, and if you mention that you're rooted, the LineageOS folks will refuse to provide any support, even for unrelated issues. Making you choose between friendly help and a usable phone is probably the only thing I don't like about LineageOS and, to my view, the biggest break from it's CyanogenMod roots.)

Re: Blocked by Cloudflare

#192

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

The cause of the problem is that your software is faulty by design. 1. IP addresses are to be used for packet routing. Certainly not for assigning "behavior scores" to users in the background. IP addresses say nothing about your visitors, my IP address could have been a complete stranger's IP address yesterday. 2. Deciding who can access half the web based on their TLS signature achieves nothing in the long run excep…

This is a very nasty comment. I was wondering if I could find some things that could lead to an exception.

But I'm pretty sure that millions of users aren't using stuff like w3m pager ( https://news.ycombinator.com/item?id=34175754 )

We're all technical here, we are the edge cases. We use exotic software / combos. Let's not get carried away here

The PM of cloudflare uses Firefox, I sometimes use Firefox and I don't notice any difference ( concerning this use-case at least).

If you want help, perhaps describe the actual use-case that is blocking you to him. He shared his email.

- country

- software ( VPN, ... )

- browser

- OS

- traceid

- ...

Either way, buying shady proxies as you mentioned is already a warning flag.

While using Firefox is not :)

Re: Blocked by Cloudflare

#193

Earlier quoted context omitted.

How is that relevant to the topic?

You asked: >> Chrome will happily collect as much private information about me and my browsing history and share them with select parties, as needed > What information does Chrome provide in this scenario that Firefox doesn’t?

Key words: "in this scenario"

Is Cloudflare using an as yet unshipped API as part of DDOS protection?

Re: Blocked by Cloudflare

#195

Earlier quoted context omitted.

When I started having this problem logging into a certain credit card co.'s website beginning with about Firefox 105.0.2 on Fedora 38, I was told by their apparently outsourced customer service that I had to use Chrome, which I don't have installed there and couldn't try. Yeah, they wanted me to use LogMeIn so they could fix the problem, too. Right. Firefox on Android was still working, though, loathe as I am to put…

[flagged]

Why would they load balance based on user agent? I can’t think of a scenario where that was a reasonable solution.

Re: Blocked by Cloudflare

#196
post #64

Earlier quoted context omitted.

> That's exactly what people are paying Cloudflare for Cloudflare actually provides this service for free (for simple use cases at least). I don't know how to come down on this issue. On one hand, I am against the centralization of cloudflare and the risks that come with it. On the other hand, cloudflare allows almost anyone to set up a simple website and serve it to large numbers of people with very little resources…

Similar mindset... also really intrigued with their developer tools as well. Workers, pages, D1, KV, etc. I was playing with a static site generator that deploys directly to a Cloudflare Pages setup, and it's lighning fast everywhere.

Psst https://ai.cloudflare.com/

Note: light use-cases ( or should I say shared models?). Not heavy GPU tasks

Re: Blocked by Cloudflare

#197

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

I have noticed that on StarLink some sites behind CF go into "prove you are human" loops that are impassable. What causes such loops? Just a challenge over and over.

> Just a challenge over and over.

It must be intentional. Not unlike the endless loop of frustratingly slow-fading reCAPTCHA challenges that don't go anywhere. The user gives up after some time, but doesn't see any explicit error or page blocking their access. I imagine it must be quite effective.

Re: Blocked by Cloudflare

#198
post #167

Earlier quoted context omitted.

Yes. And cookie splash screens! I admire GDPR's intention but hasn't it been a massive human time sink. Not to take away from your point, just that it's all a hindrance.

@adammartinetti : maybe you could consider developing a new product where you display a GDPR consent banner once , and then these settings apply to all Cloudflare-proxied websites (by passing this consent information as an additional header to the proxied site)

Sounds inferior to the "no cookies no banner" solution.

The GDPR does not mandate gratuitous and pointless personalised spying, which is the only case that requires consent. Normal operations (say a shop collecting payment details and shipping address to fulfil an order) do not require a consent banner.

Re: Blocked by Cloudflare

#199
post #179
post #84

So many privacy nuts use Chrome and don't realize this: > What about Google Chrome? > I tried all of the above in Firefox. So I naturally tried to access the same page in Google Chrome to see if I’d still be blocked. Thankfully, I wasn’t. > But of course I wasn’t because Chrome doesn’t have the same privacy- and security-enhancing designs that Firefox does. Chrome will happily collect as much private information abou…

I don't quite understand the "ads it deems necessary for me to see" comment. You will always get ads on sites that serve ads. The thing the tracking might do, is change which particular ads you get. The right solution to that, is to use an ad blocker, and to pay for sites that have an ad-free alternative. Also, fingerprinting isn't always "bad" -- any business who takes credit cards online, wants to try to exclude pe…

Tracking is establishing your identity. Try using a private mode Firefox via a VPN. Half of the web is completely unusable. You get put in unsolvable catchpa hell as punishment for being anonymous.

Re: Blocked by Cloudflare

#200

Earlier quoted context omitted.

You're conflating a downside of using Chrome and the reason they think Cloudflare blocked them.

seems like the author mentioned that in FireFox disabling "privacy.resistFingerprinting" worked. So looks like Chrome by default is allowing the server to collect Fingerprinting. If cloud flare is using that, then it is a big red flag.

Of course they are. Thats the whole point of the 'Integrity Check'. Besides, almost every website you visit collects your fingerprint nowadays.
Post reply on HN